Cross-Site Request Forgery in WP Affiliate Platform Plugin for WordPress
CVE-2022-3898
8.8HIGH
What is CVE-2022-3898?
The WP Affiliate Platform plugin for WordPress exhibits a Cross-Site Request Forgery vulnerability due to improper nonce validation in several functions, notably in the affiliates_menu method. This flaw permits unauthenticated attackers to execute unauthorized actions, such as deleting affiliate records, by exploiting a trust relationship to deceive an administrator into inadvertently triggering a malicious request.
Affected Version(s)
WP Affiliate Platform * <= 6.3.9